Microsoft is warning chief information security officers to prepare for a sustained increase in vulnerability findings as frontier models become part of routine code scanning. In a new security blog, the company said September 2026 produced a record number of security updates, close to 1,000, and told customers to expect elevated Patch Tuesday volumes for on-premises software.
The company argues that discovery speed is no longer the only constraint. Security teams must validate findings, determine severity, test patches and protect critical services at a scale for which manual review processes were not designed. Microsoft said it uses a harness layer to control how models access code, validate outputs and connect findings to triage and remediation workflows. One such harness, codenamed MDASH, is now available to customers.
Microsoft also recommended its Baseline Security Mode, which is available to existing customers within their current licence agreements. These are vendor recommendations and the record update count is Microsoft's own figure, rather than an independently audited measure of unique exploitable flaws.
The practical implication is nevertheless clear: AI can expand the vulnerability queue faster than organisations expand patching capacity. CISOs will need stronger asset inventories, exposure-based prioritisation and compensating controls so that a larger flow of findings does not become a larger backlog of unmanaged risk.
